Categories: None [Edit]

still_active

https://rubygems.org/gems/still_active
https://github.com/SeanLF/still_active
Analyses your Gemfile.lock for dependency health across the full transitive graph: whether each gem is actively maintained (last activity on GitHub, GitLab, or Codeberg/Forgejo, plus release recency), outdated versions, archived repos, OpenSSF Scorecard scores, known vulnerabilities (deps.dev and OSV, merged with ruby-advisory-db, flagging advisories with no fix and pins that sit below the fix), poison-pill compatibility ceilings, and libyear drift. Ruby version freshness with EOL detection. The same maintenance lens travels cross-ecosystem: point --sbom at a CycloneDX SBOM to assess npm, PyPI, Cargo, Go, Maven, and NuGet packages via deps.dev and ecosyste.ms. Handles rubygems, git, path, GitHub Packages, and JFrog Artifactory sources. Outputs coloured terminal tables, markdown, JSON (with a versioned, contract-tested schema), SARIF for GitHub code scanning, and a CycloneDX SBOM. CI quality gates (--fail-if-critical / -warning / -vulnerable / -outdated / -poison / -language-ceiling) with granular, committed suppression via .still_active.yml. Complements bundle outdated, bundler-audit, and libyear-bundler by adding the maintenance signal they don't, and folds their version, CVE, and libyear checks into one report.

Total

Ranking: 57,704 of 197,085
Downloads: 19,973

Daily

Ranking: 42,533 of 197,066
Downloads: 2

Depended by

RankDownloadsName

Depends on

RankDownloadsName
13,796,160,121bundler
122417,349,484faraday-retry
131396,217,197octokit
84965,921,502semantic_range
97054,050,294async
1,65423,817,658cvss-suite
16,919120,869packageurl-ruby

Owners

#GravatarHandle
1iconseanlf